MB-R328
The client is confidential and the authorization server requires the use of strong client authentication methods (based on public-key cryptography and resistant to replay attacks), such as mutual TLS ( 'tls\_client\_auth', 'self\_signed\_tls\_client\_auth') or private key JWT ( 'private\_key\_jwt').